IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability
BID:36544
Info
IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability
| Bugtraq ID: | 36544 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2009 12:00AM |
| Updated: | Sep 29 2009 10:30PM |
| Credit: | IBM |
| Vulnerable: |
IBM AIX 6.1 IBM AIX 5.3 |
| Not Vulnerable: | |
Discussion
IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability
IBM AIX is prone to an authentication-bypass vulnerability.
Successfully exploiting this issue will allow attackers to gain unauthorized access to network shares that are protected by 'nfs_portmon'. This will lead to other attacks.
IBM AIX 5.3 and 6.1 are vulnerable.
IBM AIX is prone to an authentication-bypass vulnerability.
Successfully exploiting this issue will allow attackers to gain unauthorized access to network shares that are protected by 'nfs_portmon'. This will lead to other attacks.
IBM AIX 5.3 and 6.1 are vulnerable.
Exploit / POC
IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability
Solution:
Vendor fixes are available. Please see the references for details.
IBM AIX 6.1
IBM AIX 5.3
Solution:
Vendor fixes are available. Please see the references for details.
IBM AIX 6.1
-
IBM nfs4_fix.tar
http://aix.software.ibm.com/aix/efixes/security/nfs4_fix.tar
IBM AIX 5.3
-
IBM nfs4_fix.tar
http://aix.software.ibm.com/aix/efixes/security/nfs4_fix.tar
References
IBM AIX 'nfs_portmon' Authentication Bypass Vulnerability
References:
References: